Repository navigation
Conversation
winston declared `engines.node: >= 12.0.0`, but its runtime dependency tree has not been Node 12 compatible for some time. `@dabh/diagnostics` resolves `@so-ric/colorspace`, whose published bundle uses `||=` (Node 15+) and `Object.hasOwn` (Node 16.9+), so requiring winston on Node 12 throws a SyntaxError at load time with no install-time warning. Raise the declared floor to >= 16.9.0 so npm surfaces EBADENGINE instead, and add a README section spelling out the constraint and the unsupported workarounds people are already using. Fixes winstonjs#2586
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #2586.
Problem
winstondeclaresengines.node: ">= 12.0.0", but the runtime dependency tree has not actually been Node 12 compatible for some time. The single offender is transitive:@so-ric/colorspace's published CJS bundle uses:||=— logical OR assignment, ES2021, Node 15+ (dist/index.cjs.js:1976)Object.hasOwn— Node 16.9+ (dist/index.cjs.js:158,:260)Because the
enginesfield claims Node 12 support, npm emits noEBADENGINEwarning at install time. The first signal a user gets is aSyntaxError: Unexpected token '='thrown atrequire('winston'), which is what #2586 reports.I verified that
@so-ric/colorspaceis the only package in the production tree that exceeds ES2019, by parsing every.jsfile in a--omit=devinstall withacornat successively higherecmaVersionlevels:winston's ownlib/is ES2019-clean, so nothing here is self-inflicted.What this PR does
Deliberately the minimal, non-behavioural option:
engines.node→">= 16.9.0", the honest floor implied by the dependency tree. Users on older runtimes now get an install-time warning instead of a load-time crash.@dabh/diagnostics@2.0.3pin that several commenters are already using.What this PR deliberately does not do
It does not pin or downgrade
@dabh/diagnostics. That would be a policy call about supporting an EOL runtime, and @DABH already stated in the thread that winston does not support EOL Node versions — so making the metadata honest seemed like the right scope rather than reshaping the dependency tree. Happy to change direction if you'd prefer otherwise.Two things worth your judgement, since they're policy rather than mechanics:
>= 16.9.0is the technical floor, not necessarily the supported one. CI currently exercises Node 22, 24, and 26. If you'd rather haveenginesreflect what you actually support and test, say">= 20"or">= 22", I'm glad to change it — I picked the technically-derived number because it's the one I could prove, and because it's the least disruptive to existing users.enginesis arguably a breaking change for anyone currently installing on Node 12–16, though in practice those installs are already broken at runtime. Retarget the base branch if you'd like this to land in a major.Verification
All commands run at
dd41581on Node 26.5.0.npm run lint— 0 errors (10 pre-existing warnings, unchanged from master)npm test— all greennpm run test:typescript— cleanCourtesy disclosure: I used AI assistance (Claude) while investigating and drafting this change. The dependency analysis, the ES-version scan, and the lint/test/tsc runs above were all executed and checked by me locally.
CONTRIBUTING.mddoesn't currently state an AI policy — mentioning it in case you'd like one, and happy to follow whatever you prefer.